The Wired Garage with Pops | Digital Innovation

AI, Deepfakes, and the New Social Engineering War with Bryan Fite

Hosted by Brian Clayton and Steele Harding | Digital Innovation Season 1 Episode 21

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 50:52

s1e21 2026_0310 tech AI, Deepfakes, and the New Social Engineering War with Bryan Fite

In this episode, Brian Fite discusses the implications of AI and deep fakes on cybersecurity, emphasizing the need for a proactive approach to combat social engineering fraud. He introduces the concept of the Deep Fake Justice League, a collaborative effort to address the growing threat of identity manipulation. The conversation explores the nature of deep fakes, cognitive warfare, and the importance of critical thinking in a world increasingly influenced by AI. Fite also shares practical defensive strategies for organizations and individuals to safeguard against these evolving threats.

Takeaways:

  • AI and deep fakes are transforming social engineering fraud.
  • The Deep Fake Justice League aims to combat identity manipulation.
  • Understanding deep fakes requires a broader perspective beyond just video.
  • Cognitive warfare is a significant concern in today's digital landscape.
  • Defensive strategies must evolve to keep pace with AI threats.
  • Education and critical thinking are essential in cybersecurity.
  • Privacy should be a fundamental right that we protect.
  • The narrative and perception of truth are being manipulated by technology.
  • Organizations must assume breach and implement strict security measures.
  • The future of AI in cybersecurity poses both risks and opportunities.

Keywords: AI, deep fakes, cybersecurity, social engineering, fraud, cognitive warfare, digital identity, defensive strategies, technology risks, trust verification

Sound Bites:

  • "Deep fakes can manipulate trust."
  • "Cognitive warfare is a real threat."
  • "Truth has nothing to do with it."

Chapters:

  • The Rise of AI and Deep Fakes in Cybersecurity
  • The Deep Fake Justice League: A New Approach
  • Understanding Deep Fakes: Definitions and Implications
  • The Evolution of Fraud: From Identity Theft to AI Manipulation
  • The Cognitive Impact of AI: Trust and Verification
  • The Future of AI: Risks and Ethical Considerations
  • Understanding Cognitive Responses to Manipulation
  • The Role of Digital Twins in Cybersecurity
  • Defensive Strategies Against Cyber Threats
  • The Importance of Privacy in the Digital Age

Support the show

SPEAKER_01

What I think we'll end up doing, whether we like it or not, the industry will do it or people will on their own, is if you had a digital twin of yourself, you could simulate every possible cognitive attack, every piece of propaganda, misinformation, and you could find the triggers that work for you. And if you can find the triggers, then you can find the cues and you could break that cycle.

SPEAKER_03

It's like building your own immune system.

SPEAKER_01

That inoculation cover. It's called pre bunking.

SPEAKER_02

From cloned voices and synthetic video calls to AI written fishing at scale, Brian explains why defenders need a deep fake Justice League mindset to keep up. So, Brian, what sparked the idea for a Justice League and cybersecurity? This thing fascinates me.

SPEAKER_01

Yeah, so I guess we can go back to when I was a kid and watch the all the Saturday morning cartoons when there were only three channels. But yeah, it was inspired that. No, seriously, back in 2006, I actually published a Sans gold paper that was called Corporate Identity Fraud. And at that time, corporate identity fraud uh was was kind of a new subject and web pages were just coming out, and it was a lot of cyber squatting. And so back then it was interesting, it was all trademark and brand. And what would happen if somebody kind of were violating a trademark or brand and somebody saw that their trademark was being abused by a fake wapes website trying to defraud or confuse people? They would take little pictures, photocopy that, get them to a lawyer, and those lawyers would take a package, and it would be FedEx that they had chain of custody and timestamps, uh, and they would um essentially serve up at some point a fictitious name in some country that had no jurisdiction in to ask them to kindly take that down. Uh, you know, that was in 2016. The state of the art was essentially um, you know, humans doing human things with lawyers. And the litmus test was um, you know, is it is it actionable? Can we can we sue or do something like that? And so uh, you know, years go by, you know, 15 years later, I'm ready to, you know, publish another paper. And I went in and said, well, hey, let's let's look at the state of the art. 15 years, I'm sure everybody has sorted this out. Um, you know, spoiler alert, that was not the case. In fact, what we found that there were even more um corporate identity assets versus, you know, not domain names. Well, there are even more domain names. We have the generic top-level domains, and so that attack surface is getting bigger. We have our social media accounts, and so the number of assets has, you know, exponentially increased, but the practice uh takedown and how you serve up and how you detect and protect people has not kept up at all. And part of that paper, uh, there was some theoretical, what I'll call point of origin hacking, again, influenced by years of great science fiction and fantasy and total recalls and running man of how humans can be defrauded and confused. But now it seemed that we were multi-domain, meaning it wasn't just the online domain. There were physical ways that, you know, caller ID and all these identity assets that are used to commit essentially fraud. And we named that paper the future of fraud today. And so that came out in, you know, it was 2021, started doing some things with these weird machines that we call uh large language models, and was really seeing the possibility of, you know, being able to create really effective artifacts that would confuse people, caller ID spoofing, all right, that's you know, been around for a long time. But if you can add some voice cloning and you have the right pretense, it started making ransomware crime or kidnapping crime, uh, again, targeted primarily at uh individuals who might not be so tech savvy, but you know, we've passed the Rubicon. With six seconds of audio, you can have a very effective cloning of a voice and the other artifacts, the video artifacts. In fact, there is an entire industry building up to try to prove that, in fact, I am me right now and not uh MoCap Avatar. Wow. So I think we needed to be able to uh address that. And because the problem has been um, you know, the solutions haven't been forthcoming for so long, we are going to need superheroes. And that's when I formed the Deep Fake Justice League and went on a you know journey to find the superheroes for the Justice League. And that that uh you know that journey began. Hadn't been to DEF CON in many years uh for various reasons. It's just the desert in the summer. Why do that to yourself? But I did have to go find uh some of the good researchers. And so uh I went out probably would have been um in 2024 after we had done uh some DARPA solicitations and an SBIR for the state of Indiana, to where we really started to understand how the large language models, certain computer vision models, and all of this explosion in AI and really high performance GPUs on gaming machines, we were, we we knew that the price for token was going to go down. And we also sensed that there was something going on. If, you know, your five senses, but there's this cognitive piece. And I didn't have uh terminology for it, but I knew inherently that it was psychology and psyops from the Cold War days that were being used to target people. And if if these weird machines got that bit right, you know, as a sidebar, our large language models are susceptible to all of the same social engineering techniques. So when you hear about people jailbreaking a chat bot, that's really using those kind of social engineering skills or cognitive attacks and are very effective. So I knew I needed some some math, and I knew I needed some more scientists in my deep fake justice league. So we went out to B-sides, that would have been in 2024, specifically looking for Dr. Matt Cannum. And I sat through three presentations out there, one by him, uh a few by the folks at Trail of Bits, and they had a taxonomy. So they had a way to describe these attacks. Uh, think miter, um, miter attack, defend, but for for your your noggin. And so uh seeing that, getting involved in what you know, I was later to find out was a small but growing community in the cognitive um security institute. I was fortunate enough to be invited to um their uh uh annual event called Cognicon at George Mason University. So think, you know, think tank. And it was it was eye-opening. And at that point, I was hooked, and I'm in that community now, and I've been recruiting heavily for the deep fake justice league. Some of the members are very overt and happy to talk about it and take on the mantle of superhero. Others kind of just want to lurk and and help with the technology and help the community. But I've I've been meeting a lot of very interesting people. And in fact, I just went to Cognicon ConnectCon 2026 down in Tampa, and it was was really eye-opening because now not only can we see these artifacts um that are being used to abuse trust, we're also understanding the physiology that goes along with it and the ability to actually induce behavior through certain cues. And so that's all very interesting, scary, but to know that there are heroes out there, you know uh to put a finer point on it, the the reason we needed a deep fake Justice League was to have a nice hook for a Packet Wars game. So it is a Packet Wars campaign, and we had built um all sorts of battle briefings. Uh, and the first one we did was at Korn Con 11. And so, as you know, uh you've you've played Packet Wars before. We always have a battle briefing, and it's a one-pager, and we it we call it Serious Fun, P-H-U-N, it's edutainment. But the scenario was that there there was a rogue AI trained exclusively on Mr. Bean, vintage Mr. Bean movies, and that the AI was hellbent on cloning everybody at CornCon and turning their picture into a Mr. Bean. And so uh we've played on that one. We've we've had a couple others. We will be having uh more games this year. Uh, and of course, we will make those available to the community. But out of that, uh, we started seeing the you know the best deep fake tech that I've seen, the most cost effective are these little masks that you can put on your face, and they they are legit. They work, they fill full cameras. Everybody's using the same computer vision model. So we have a series in in there to try to defeat. It's called Hiding from Robots. And we're we're having a good time with it. But again, it's all to identify what we'll call IOBs, indicators of bullshit, if you can believe that if you have to, and visual cues to try to figure out how to short circuit system one and system two. And that's where the cognitive piece comes in.

SPEAKER_03

So there's there's so much to break down there, but thank you for that lovely kind of roadmap on how you got to the Justice League and the different components of that. And that does sound like fun with Cap O P. Kind of dissecting a piece of that. So you mentioned voice cloning, you mentioned GPUs. Can you kind of just break down how what would you classify as a deep fake? And is that only restricted to videos?

SPEAKER_01

Well, no, so a multimodal deepfake, if you're talking about the ultimate deep fake, it would essentially be an evil twin or an avatar that you control or synthetic that would have all the characteristics of your target. And if your objective is to get somebody to violate trust, so if I'm going to deep fake you to somebody who trusts you, you know, what's my end game? If my end game to, you know, defraud you, uh, to get access to some of your resources, or to get somebody who trusts you to do something on your behalf. So you could think of the classic crimes of business email compromise, which, you know, they're they're calling whaling or pig slaughtering to get people to do Swift transfers. That was for a while there, that was the hack de jour. Yeah. We, you know, you could imagine if you want to manipulate the stock market, if you can get a CEO to say something really bizarre and you're doing spot chain trading, that would be a way, you know, North Korean worker fraud, where people are actually usurping identities of real or creating fictitious people in order to get employment to bypass the sanctions. And apparently what's what's funny is um a lot of people who've been caught up in that scam, big big businesses who are, you know, after COVID, you know, nobody goes in for interviews anymore. And we're really a distributed workforce. So how do you verify identity? And if, you know, the best place is if you can't steal somebody who already identity who already has access, create an entirely new access and go through the onboarding period. And so that's what they're doing. They're getting hired in fake people that are delivering real work. And apparently many of those workers are very competent, good coders. And they, you know, they work hard and work late, and they typically uh, you know, it's the it's the gift that keeps on giving because they become integral to the system. And originally the the those campaigns were, again, like I said, just to have them get salaries so they could send that back to the homeland and and bypass the sanctions. But, you know, it's a very intricate and it's a very sophisticated um form of crime and it's evolving very quickly. So now if you talk to any HR folks, you know, they'll they'll they'll know that they're having to vet people early on, and it's very difficult. And of course, there's um the it's a syndicate, um, and I don't use that term lightly. Uh, the scam involves lots of people. Some of them are knowing participants, and others aren't. So when you see these jobs that say, hey, work from home and make lots of money, those are the mules. So they'll basically, the fraudster who's uh personating this fake identity will give the mule's address, the company who will onboard them, they get the job and they start work on Monday. The FedEx has to go somewhere, and send it to North Korea is not really an option. So they send it to whoever the mule is, and they will set up that VPN and then they get a remote terminal session. And so some of these folks are actually, you know, there were farms of these where there are, you know, 20, 20 systems simultaneously uh from different companies, and it's big business. Wow.

SPEAKER_03

So I mean Facebook said that a huge percentage of their not a huge percentage, but like 10% of their ad revenue was scams. Oh, no, sorry, which one? Facebook. So meta. Facebook's revenue was like from scams, uh, I think they said. The the the numbers are out there.

SPEAKER_02

There there's a few things out there, like there are products. I want to I don't want to name it product names, but what they'll do is so you say a few words, you then you can type, and it tries it has your voice talking for you. You know, you know, so kind of, but it's in a friendly way, friendly use way, right? So it's it's it's an advantage for me to save time or whatever it is it is, but it's almost like desensitizing me or whatever you want to call that to this, to where it becomes a norm. So there's a and I've also talked to help desk centers in like India. When you talk talk to India or something like that, there's a lot of people say, Well, I can't do that because it's foreign, you know, our our cut our clients don't take to that well. Well, now they have a tools that will make them sound like they're from Atlanta, right? No speech. Yeah, so there are some legit so there, I mean, so look, right now it's kind of like opening a door to have you allow that in your world, but yet they're just swipe in there and and and steal.

SPEAKER_01

You know what I'm saying? So I yeah, no, I know exactly what you're saying. So everybody, and and you know, in the video production business, um, a lot of people are using filters. Before that, they were having fun because we were all locked down, little avatars, or let's put the the you know, the whiskers and the cat ears on somebody. So all that technology was building up to, you know, full on deep fake. Used to have to have a green screen back here, but I can have the AI sort that out for me. And it and it's it's being used everywhere in post-production. So I don't think, and and that feeling that you get when you look at something that's called the Uncanny Valley, when it's when you look at it, you're like, that doesn't look exactly real. It looks like it's been airbrushed. Um, but you know, airbrushing and that kind of stuff used to take a lot of time. Now it's a feature. And everybody is out there trying to offer these types of enhancement tools so that you're a more effective communicator. Um, my first experience with commercial AI was grammarly, and it was on one of the SANS papers, and it was the worst experience in my life because it was enforcing on me somebody else's version of how to speak. And it it was just, it was a terrible, and I won't, I won't mention which paper it was because my advisor on that one was I was not very happy with that experience because I don't think they ever read or understood the content of the paper, but they did live and die by what Grammarly said. And to your point about um, you know, 10% of the ads being potentially bots. There's an interesting thing about the attention economy or subscriber economy. And that's really what we're we're all about is a subscriber economy, whether we like it or not. And I worked for a company that had very expensive subscriptions, and I was in a meeting, and we were pretty sure we were positive that users were sharing passwords. And, you know, it said that's bad as a security practitioner. This can't be good. And I don't know who said it, but they somebody said, well, somebody's paying the bill. And then I go back to what Graham Nielsen and Vlad did when they did their Uber hacking stuff. Gosh, it's been maybe 12 years ago, 10 years ago, whatever. And they had created and showed there was a flaw that they could basically create fake identities, spin up Twilia numbers because uh the way that um uh Uber there verifies that you're a human is with a phone number. And of course, you know, that's caller ID should never be used as authentication because it's easily spoofed. And just because you have a phone number doesn't mean you're human. And what they were able to do was, you know, effectively create something in the neighborhood of 10,000 legitimate Uber accounts. The thing about that, what was interesting, there was a lot of different interesting bits about that one, but the the one that got the most eyebrows raising was that every new subscriber got to get $5 in credits. And so you can imagine when you're getting 10,000 of those. So I don't think that, you know, those people ever had to pay for Ubers for a long time. And at the end of the day, you're like, even when Uber knew about it, they never put controls into fixing. You're like, why? Well, because their valuation, I mean, they don't own cars. What do they have? They have identities. And if the advertisers really don't know that they could, they're not humans consuming it. And you look at Spotify, everybody who's trying to jack up their views, go rent a botnet. So, you know, it and the price of of each of those consumers is getting less and less. So, and and now we've we've kind of crossed another Rubicon where we have full synthetic stars, you know, that have their own, you know, they have their own Reddit channels and they get to talk about us. They're coming up with their own language. So it's moving very quickly. I don't know if it ends poorly for us or not, but we're gonna get find out.

SPEAKER_02

Yeah, we were talking to uh a friend of mine yesterday last night in an interview, and he's a guitarist, and we were talking about these this AI groups and music coming out, and it's and it's all but done by AI, and you think it's some big rock group that's touring a nation, there's not a human involved. And it's just amazing some of the things that people are and they're hitting the charts, right?

SPEAKER_00

Yeah.

SPEAKER_01

I it you know, that's it's creating those artifacts. So if you look at how we're trying to so multimodal. So if you can't believe your eyes, can't believe your ears, how do you verify that you are who you say you are? And so, you know, for for things like the um the ransomware or, you know, your your grandchild is in a prison in Mexico on spring break, you know, go down to your friendly neighborhood, whatever, and send us some Bitcoin. By the way, they really have good tech support because the tricking people to do something is the easy part. It's actually telling someone who was used to using cash to get on a bus to go to the one ATM that has Bitcoin and walk them through it. They will stay with them on that call the whole time. So, you know, they're very dedicated to the to the the art and science of fraud.

SPEAKER_03

What uh what incident or cultural moment convince you that you know what this might be a crisis or we there's gonna be some abuse of this coming.

SPEAKER_01

Well, for me, it's kind of like my nature. I've got this concept of point of origin hacking. So at some time when you look at a system, somebody was the first person to say, oh, this is how I would break that. And so for me, that's how I look at systems, but it it had to be, I want to say, uh the running man, you know, when Schwarzenegger basically has his face mapped on, and it was like, you know, that to me, I was like, or what they live, you know. I so I'm heavily influenced by that. So I think that was probably when I saw that, I was like, yeah, we're doomed, knowing the trajectory of uh technology. But I'd say for for me in this particular time, we did a deep fake. I worked for an organization who uh had a was doing a deep fake exercise at tabletop, and they had the budget was something like you know, north of 150K to produce like 60 seconds of a fake CEO, you know, get reading out some stuff to the the employees with the end game to get the employees to click on an email that was going to come in. And six months after that, that same exercise with a higher level of fidelity, 50 bucks. And that was only 50 bucks because people were still learning how to use the tool. And so when we do, there are a lot of models. There's to train these models, that was the other thing, and maybe this is the the bigger one. You know, there was a GPU shortage for a while because everybody was building these giant big models and there were no GPUs available. And then Deep Seek comes out, and now nobody's training models again. There are a few people out there doing it. But all of these models, even the big, they're all kind of the same because they've all scraped the same crappy internet to build their, you know, so I uh well, I won't I won't go into too much about the kind of models that I use, but I don't use cloud models myself. Uh I don't like large models. I like small purpose-built models. Um before three years ago when we started doing this, and that's probably when I saw what we could do with small language models and that the fact that the cost was was going to bottom out so that what used to be very high bar, high barrier to entry, nonexistent. You don't even have to s have skills. You can just tell, you know, your assistant what you want to do, and it'll go out there and vibe everything, which by the way, is none of this is good. I think it's good for rapid prototyping, it's good for learning. Anyone who starts rolling vibe coding and agenic everything into production, well, we're gonna see. We saw what what's happened recently with Claude uh or Claw.

SPEAKER_03

Um, and I I think they're talking about having AI review its own code, having a gentic agents review its own code. So eventually you're gonna have code bases, tens of thousands of million lines of code that's not reviewed by a person.

SPEAKER_01

Right. And it's gonna, so you know, with model context protocol, so just a large language model. So NIST AI 600-1, that is to me what I call the dirty dozen. It's my North Star. They're the 12 areas of harms that humans can uh uh that that can be uh uh realized if you don't get generative AI right. So we're all familiar with confabulation, which is hallucinations. Um so an AI model will always try to give you an answer because it just predicts the next character in a prompt. Um so you know, your my calculator doesn't hallucinate, but my LLMs do. And it's the it's the the non-deterministic nature via the temperatures and everything that make them powerful. But at the same time, if you're you know betting mission critical stuff on it, your AI shouldn't tell you how to hurt yourself. So it shouldn't tell you how to make rice and poison. They shouldn't tell you to hurt yourself, they shouldn't tell you to hurt other people. So that's the 1230 dozen. And what we found is that you can social engineer or jailbreak pretty much any large language model. And the bigger the model, the easier it is to break it. And so this idea that you're gonna put guardrails, which are essentially other large language models, around that, mathematically you'll never solve that problem. And nobody wants to talk about that. If you're if you're uh if you have ever studied LangSec, I think there's some some Langsec techniques that could be used, but this is a mathematically impossible. And then if you start having models monitoring models, monitoring models, the level of complexity and the seams that exist, no. I'm going the complete other way. I want highly optimized code. So if I'm going to use uh, you know, a large language model to do something, uh, I just want to have that very purpose-built function. We call our ours eggs, emergent generative generators. They're very small, they can easily be tossed. I do not let any of the eggs talk to each other directly. I put them in egg cartons and they communicate through highly controlled communication paths, and I have forensic monitoring and what we call total telemetry on all of those. That's not how people are developing these in the really real world. So, yeah. Million lines of code, humans don't review it today. And just because it's open source, people think it's being crowd uh reviewed, and that's not happening.

SPEAKER_02

So, what what do you think is the biggest threat? Fraud, disinformation, or reputation warfare?

SPEAKER_01

I I I I think fraud is what we're experiencing now, and it it it it's very effective. I think uh the cognitive impact of what's going on is is what's even more scary, where we're already divided. I mean, we've got a very perverse system set up where the algorithms re reward division. Yeah, I my internet was cats, you know, and little, you know, things. Now it's it's as soon as the uh whatever's gonna get you, it's gonna be clickbait, rage bait. I've pretty much unplugged from most social medias, I call them antisocial media. Yeah. I curate my own stuff. Now there's there's obviously a problem with that, and then I get into my own echo chamber and I don't have diversity. That's why I've adopted something that Wynn Schwartau calls critical ignoring, because we are essentially our system one and system two are being overridden. So, system one, that's our kind of muscle memory. You have four responses to stress as a human. And this is, we evolved this way. This is how we we became the apex predator fight, flight, fawn, or freeze. And those are the system one. So when you get fished, an effective fish, with even just moderate knowledge of who you are, those cues that normally you would see and pick up on, they're overridden because of one of those four responses. It's like, oh, you're gonna miss out on this great deal, you know, or hey, I'm somebody who thinks like you, you know, come to this limited time event. And so clicking, if that is the desired uh uh, you know, result of the of the you'll click on that. So simply taking a minute to that reflex to stop, then system two kicks in. And system two of your cognitive, it's expensive, but because it's doing you using your neocortex, it's doing some critical thinking. And you're like, if so, if you practice things like two, if you acknowledge that there's too much information, so physiologically, our senses can only take so much bandwidth. We are overwhelmed. You know, humans actually cannot multitask, even though people might say that they don't. They could just, you know, time slice, right? And so with that much stimulus coming out, you we are not built to handle this. And in Wynne's book, um, you know, Metawar, he goes into all the details about, you know, what our theoretical limits are on our ability. And some of the best ways to avoid that is to unplug. So if it's about manipulating human behavior, so we can easily manipulate human behavior to create a human botnet. So and and that's when we cross domains, that's when I start to get concerned. So swatting, right? SWATT is a thing when you want to get back at somebody, or you know, you can't hire lizard squad to take out this, you know, rival, rival gaming group and just call the SWAT teams, you know, report them as something that there's they've got a hostage, and all of a sudden those guys are offline. Or if you want to create a traffic jam, just go on socials and say that, you know, some influencer, I don't know who it might be, who's got enough followers. Hey, show up, we're giving away five PS5s. First, first 10 people there, get it. And multi doing that on multiple domains with multiple communities, that's what I'm worried about. Um, and and that cognitive Pearl Harbor, I mean, we've gained a lot of it out. That's what a lot we do with the packet wars. That's why we're trying what we're trying to prevent. We're trying to give some critical thinking, bullshit detectors out there so that our humans' cognitive noggins are protected. I wish I had a tinfoil hat for you, but I don't. Yeah.

SPEAKER_02

But do you know we got things like as little as, and this for you would you'd probably come back and say it's not little. Alexa, you know, my wife and I will be talking about, hey, we gotta get some dog food. Next thing you know, on one of the Alexa Echoes, you'll see a video thing about dog food being sold at Amazon.com here, you know, buy dog food for on sale. I mean, just things that there's no way this stuff is coincidental that these things hit our phones or hit our our screens after we just talked about it. You know, it happens too often. So there's to us and guiding us and manipulating our patterns by just hearing us talk and and live.

SPEAKER_01

Yeah, and and you know, I mean, that's part of the price we pay. You know, if you you're getting there's nothing for free, right? If it's free, you're the product. So, you know, we we we've they've boiled the frog slowly. Like I was so so much better when I was younger and shaking my fist. Uh, we wouldn't have had any of these robots um in the in the house who are always listening because out they have to always be listening, right? They're sampling. And if you look at the fine print, they're they're gonna send some of that back just for quality control. So, you know, all the details are in the in the EULAs, which change all the time. So that's not human-friendly. We don't read it. And we've kind of given up all of our expectations of privacy, you know, for whatever convenience we're getting. But no, they correlate that data. It all that data is coming back, the metadata, you can the amount of entropy involved in each individual's um surfing habits, as it were, you have behavioral, you know, PII, right? Personally identifiable information. That was the gold standard for criminals and trading on the ground. That's chump change. Then it became medical records so that they could commit medical fraud, because you know how long it takes to for a billing system. So you know the perfect crime, the one never detected, or the one that's detected like a year after you're gone and you've already made your getaway. But these perfect, these behavioral identifiers, these fingerprints, you can have incognito mode and you can you can put have as much operational security. But if you go do the same things over and over, your biometrics, the where, you know, the gate that you have, even using wireless interference to detect humans and even, I mean, some of the scientists, they can they can detect medical issues with some of those signals. If you have enough signals, in fact, that's uh some of the first work I ever did with Sergey Bractis. But gosh, that would have been back in Schmoo days. His research was all around give me a million lines of of logs. I don't care what they are, and I will tell you something about what's going on. And we did that. We did that at DEF CON. We set up a bunch of um Bluetooth monitoring stations, and he basically was picking out people. Oh, yeah, this person has some kind of they're either drinking a lot because they keep going to the bathroom. And you could profile, but if you have enough data sets, those distributed data arrays, you can start to build what I'll call low-fidelity digital doppelgangers. Now, the beauty of that, there is a positive of this. In fact, I did this recently. I've kind of built through some of these exercises, there was a NIST fishing golf tournament that the Cognitive Security Institute put on. And essentially, they have a taxonomy for um uh grading fishing scams. So, and that would include anything that's getting you to click on something, right? So multi-stage attack and the like. But through that process, imagine if you had it. So we got to simulate all the different phishing scams. And I found my blind spots. Because the blind, you know, you never see the one that gets you, the one that gets you to click. And I don't know that I will want to share my profile with everybody, but I will say it was very telling. And now that I know about it, I'm I'm I have extra guard that I don't do that. And so, my what I think we'll end up doing, whether we like it or not, the industry will do it or people will on their own, is if you had a digital twin of yourself, you could simulate every possible cognitive attack, every piece of propaganda, misinformation, and you could find the triggers that work for you. And if you can find the triggers, then you can find the cues and you could break that cycle. It's like building your own immune system that inoculation cover. It's called pre-bunking. There's a there's a piece in that called pre-bunking, which again in Wynne's book, and it came out of Cambridge. And and unfortunately, all the good research right now is out of out of Europe or the UK.

SPEAKER_03

So on that subject, so inoculating yourself against what you'd be susceptible to ahead of time, are there defensive tools, that being one of them, that you think of when we're in this environment now where we've got AI, we have disinformation, we've got fraud, everything is going so fast. What defensive tools do we have? Are they keeping place or pace? And are there any areas you think we're just generally blind or we have some decent blind spots?

SPEAKER_01

Yeah, so uh it's asymmetric like it's always been. We defenders are at a disadvantage. We can't even really have conversations about this in the current political climate because when you start talking about red pill, blue pill, that means something different to people now than it used to be. And uh, you know, people seem to be happy in their own echo chambers, uh, and that feeds on itself. And so obviously, all the news that you get support your ver your view of reality. You know, in this research, everything I perceive, smell, hear, touch, think, that's my reality. Would you agree with that? Yes. Yep. And likewise, everything that you perceive and think and are is your reality. And if we were actually in the same physical space in the same temporal, that might suggest that alternate realities coexist at the same time. And that's not quantum Schodinger's cat stuff, right? But it's it's fact.

SPEAKER_03

A great example of that is the sphere in Las Vegas. There is this, um, I don't know what to call it. Basically, if you're to walk into a a place and like something in an art gallery, uh, I forget what the term is.

SPEAKER_01

So parallax, your view is going to be different than the person.

SPEAKER_03

It's the sound. They have a speaker, and you can be standing next to somebody, you will hear a different instrument than the person standing right next to you.

SPEAKER_01

Yes, the spatial sound, and that's also so those are playing with that type of temporal distortion of just the delay that makes it, or beaming sounds to a certain place, that is the next frontier of deep fakes, where you you will, and there's there's they're actually using some of this music in in movies today where the music has it's there's not really like what is that means? It's just sounds and it's designed to increase your anxiety, and it's mathematic. You can't, you know, just like you can actually have sounds that will make you calm, you can you can have the inverse of that. So that technology is moving faster, it's being automated, and we are still have people that do not believe that we are we are in cognitive warfare right now. And, you know, misinformation, disinformation, marketing, propaganda, whatever you want to talk about it, our tech is we, you know, it has surpassed us. And we have to figure out, you know, what does it mean to be human and what are we what are we getting out of this exchange with our tech? So for me, the easiest way to kind of deal with too much information is I I meditate, I'm unsubscribed to a lot of stuff, I force myself to go out. What can the average company do? The one best thing, because people are still getting got mostly via email, is to disable all links, right? It just kill them. And and that time would say, okay, I'm reading this now. Oh, I want to click, oh, it's not convenient, that kicks you in from system one, reflex, to system two, critical thinking. And all of a sudden those scams aren't as effective. Now, the multi-domain bits were, I mean, I have some rules. It's like, you know, I have physical controls. So I put a physical block over my camera, right? If I have listening to devices, even though the button that's not a button says that's not listening, I don't have them in places where they shouldn't be listening. I assume breach, I assume that the EULA gave them the right to do something. I mean, we just had a recent, saw the Super Bowl, right? I mean, that there were some commercials that were pretty interesting. And now we we have this person hunt that's been going on for three weeks. It's it's dominating the news cycle, five minutes every every day for every show. And I I feel terrible for the people. But the idea that they could retrieve the unretrievable, that data, that camera, that film video should was never there, but yet it was there. And I'm wondering if it took a court order or a bunch of forensic folks or just a call from the right person. So uh, yeah, Brian, I think we have to assume that everything is listening to us at all times and conduct ourselves accordingly, you know. I mean, the option is not to go Ted Kaczynski and get a cabin in the woods somewhere, but it's got to be conscious. So, you know, hackers back in the day were so worried about being tagged and tracked. And, you know, here we we bring our own tracking device, right?

SPEAKER_03

Yeah, right for them. What what top three defensive priorities would you recommend, maybe uh in the next quarter or the near term for a company that you're walking into or a medium-sized company?

SPEAKER_01

I never take inbound communication. That's my number one thing. So you you call me, even with a caller ID, unless I'm expecting your call, you rolled a voicemail. Um, and that that introduces a delay. The click the not clicking, turning off all URL links. Um, because because then if it's important enough, I'm going to go to my known good site. So if assuming my DNS hasn't been hijacked, I'm gonna have, you know, uh a little bit there. And then I think we've gotta uh we've gotta start teaching uh critical thinking. And maybe the the right now the only place there's budget for this stuff is the once-a-year obligatory training. So I prefer Cato mode, and I don't know if you ever watched the old Pink Panther shows, constant attacks. Like Cato's deal was Clouseau would come in and and he was always supposed to attack him. And it didn't matter what. And of course, because it's a comedy, he would always attack him at the worst possible moment. The one time when he shouldn't have attacked him, he would attack him. But I I don't think once a year is good. I think you can gamify some of this stuff, but you've got to get people invested in it. What's in it for them? And maybe what's in it for them. I mean, on the harsh side, you keep your job, you stay viable, you know, you you don't get ripped off. Um but you know, education, again, if you're if they're targeting system one, we'll never win at system one because that's how we survive. That is when we ran away from the the things that were gonna eat us. You know, that's that's how we've stood up and when it was a fair fight, when you actually had something you could hit with a stick. We don't have that now. These are algorithms that never sleep. You said three things. So the education piece there, but if you want to take that education piece to the next level, we need to have our own cognitive digital twins. And that has its own set of issues, because if I'm training a model that's gonna be know me, the good, the bad, the ugly, I wouldn't necessarily want that to get out anywhere, right?

SPEAKER_03

Digital, Brian, I'm gonna shut you down.

SPEAKER_01

Yeah, or maybe they take uh take over, uh, or then I can get some uh extra sleep in the day. But with a digital twin like that, or a purpose-built, not high fidelity, a digital doppelganger for a very specific purpose that I could put into a simulation and send a million phishing scams, send a million SMS scams, and find out where my blind spots are. And then I could custom build either my training regime just for the vulnerabilities that I have, right? We cast our net, so we've got an hour of training for you, and I'm gonna train you on all the things. And maybe I don't spend enough time on the one thing that's gonna get you, right? That's why we it doesn't work, right? So I think anything that we could do to treat, to find those blind spots and give us a little bit more advantage as far as understanding our weakness, know thyself, uh, that would pay big dividends. You could argue also least privilege, assume breach. Just assume that you're gonna get fished three times a day and you're gonna click on one of those. If you if you don't have internal credentials, if you're authenticating, but now the user experience is friction. That's the thing.

SPEAKER_02

It's the Instagram, it's the ease of use, it's the, you know, you're you're fighting the uphill on these things because everyone, everyone is, is, is, is, uh, is seeking these things quicker and quicker. I mean, I get pissed off if I gotta turn on my computer here and I'm watching the Olympics and I gotta click four or five times to find the sport that I wanted to go to every day every day. Why doesn't remember that? You know, it's just sad.

SPEAKER_01

It is interesting. I canceled one of my subscriptions doing this resist unsubscribe thing, and uh I am so mad because the algorithm I had my algorithm was trained and I didn't get any junk mail. I mean, that was the promise of giving up all my information. And now that I'm not on the subscription, it's just throwing. Oh, I'm just like, but you're doing this on purpose. So I'm almost, I'm almost ready to create or pull out of storage a couple identities that I can, you know, kind of a greenfield opportunity, and I'll feed my algorithm all my kitten videos and only look at those things, and they can feed me uh those, and I'll watch their stupid commercials in exchange for just seeing the things that make me happy.

SPEAKER_02

So when you hear people talk about AI and cyber risk, do you hear what leaders do you hear? And and he's kind of slack. And shake your head. Like they've got it wrong. You know, they're talking big, like you know it all, AI and risk, but they're they're way off base. Or or they're 1980s, maybe.

SPEAKER_01

I think it's it is 1980s. They're trusting their mechanic to fix the car. They're they're trusting the vendors who inherently corporations, you know, if they're publicly traded, they don't necessarily have an obligation to their customers. The obligation is to their shareholders. And it, you know, if you play that game to the end, they will extract every bit of value. Um, and and you know, I don't know if you've seen the talk truck um uh Corey Doctorow, the shittification of everything. And it's the new model that we have. So I think I think that people are underestimating how damaging this technology is. We I think we will look back in this age, assuming we survive as a species, that this device was the worst thing we've ever created. It was worse than, you know, and and that the the purveyors of this technology understood it and that it is designed to be addictive. If you look at the uh physiology, the endorphins, that everything that gets released when you get a like or if you don't get a like, and we are little rats in a maze, and and we've trained these things very well. So I would think that I think people think when you talk like that, that you're a conspiracy theory person, and that, you know, the tinfoil hat, it's there. It's obvious. The the math is there. I don't know if you saw the social dilemma documentary. I think it's really good. You're seeing a lot of the tech bros are coming out and doing documentaries and interviews. A lot of people are leaving, um the, you know, and moving off somewhere, taking the taking their money and moving away. I I love the technology. We have to learn to coexist with it. So don't get me wrong, but it is not without risk. If we look at the early days, uh even I mean, the breach, Texas was one of the first companies to go through a breach, and that breach was we over-disclosed on that one, maybe 2,500 Social Security numbers leaked. The FTC had the deal with the FTC was that they got to live uh on campus for 20 years. I mean, 2,000 Social Security numbers. I mean, what's the the breaches that are happening now? And so we haven't gotten laws. We do not have software liability laws. We have, we have, we do not have basic safety. I mean, you you can't buy a car, you should not be able to buy it. If you buy a car that is known to have flaws and kills people or harms people, there's gonna be a recall. You're gonna have, you know, we have never had a software liability case. So I think it's it's goes back, Brian. It's it's it's the bigger issue. We just trust, we like the convenience, we want things to be cheaper. We don't mind upgrades and this whole cycle that, oh, we need another. I pay extra to have my phone use the user interface from three years ago. I quit messing with my UI. I can't opt out of that because, you know, I'm assuming that those security patches that are coming in for the iPhone are are, you know, they don't give you much transparency there. But we've rewarded that behavior. So we're really given a lot of trust over and assuming that if they have a motto that says do no harm, that in fact they would do no harm. But it's probably do no harm to my shareholders, not necessarily my customers. Right. Right.

SPEAKER_03

I've got one thing that I I just want to slip in here before we we kind of wrap up. What would you tell people who say they have nothing to hide?

SPEAKER_01

You'd be surprised. Um, I don't know. If it's if it's, you know, you probably probably do have something to hide. Um, unless you'd do, would you keep a diary? Would you want the world to see your diary? Would you want to some of those weird thoughts that you might have when you're cre and created and say something that could be taken out of context? So I think that privacy, if if you know, privacy advocate, it's all right to have some privacy. And you should be able to have your weird thoughts without somebody using those against you. And you don't have to be a criminal to value privacy.

SPEAKER_03

I think that's kind of the rap it gets nowadays, uh at least from some folks. I mean, with the examples that you shared earlier, just talking, having it recorded, and now they have your voice. Don't you think you should have a right to privacy? Or they take your phone, they get your telemetry data from here, and now your insurance premiums are raised for right because you're going to do harm.

SPEAKER_01

Yeah. I I love the Constitution. I think the Constitution has a lot of good bits in there. Section 230, for some reason, we suspended all these great laws and stuff that we had to protect um the media companies because this technology was new. Well, it's not new anymore. I mean, I I think that it needs to be if somebody says something, they should be held accountable for that. You've got to know if somebody really said it. You know, don't have to be disinformation to change the narrative or pwn the narrative with, you know, alternate realities coexisting at the same time, dueling narratives. You're looking at the same exact, you know, thing and interpreting it completely different. I was at the uh uh first ConnectCon that I went to at George Mason, and there was an opportunity to put in what I've been, you know, thinking about what is what is the currency of confidence? The currency of confidence, it's it's transparency and objective truth, facts, right? And I I said, hey, it's the currency of confidence, it's a transparency and objective uh truth, facts. And almost uh in unison, grasshopper, you're so wrong. Truth has nothing to do with it. Reality is the story, it's the narrative. And that's what that works that we're seeing. So if if having your private secrets out there or the things that make you you can be used against you, and that there's an algorithm that has no ethics or morals or incentives not to do that, that's the weird machines that we've built. That is the ecosystem that we have. That is why the stock market is where it is today. We we've got to re-evaluate as humans, is that you know, we'll make good pets for a while.

SPEAKER_02

All right. So we're gonna park it here for today. All right. If you take nothing else from this conversation, let it be this. You can't outsource your judgment to the algorithm. The bad guys are always gonna use AI to move faster, sound smoother, and look more legit than ever. Uh, but you still get to decide what you trust and what you verify. So huge thanks to Brian Feit for sitting up with the Deep Fake Justice League and dropping real world playbooks instead of buzzwords. Go check out his work. Thanks, Brian, for joining us. Cheers.